Users Guide

Table Of Contents
urg (Optional) Set the bit set as urgent.
capture (Optional) Capture packets the filter processes.
count (Optional) Count packets the filter processes.
byte (Optional) Count bytes the filter processes.
dscp value (Optional) Permit a packet based on the DSCP values, 0 to 63.
fragment (Optional) Use ACLs to control packet fragments.
log (Optional) Enables ACL logging. Information about packets that match an ACL rule are logged.
operator (Optional) Enter a logical operator to match the packets on the specified port number.
The following options are available:
eq Equal to
gt Greater than
lt Lesser than
neq Not equal to
range Range of ports, including the specified port numbers.
NOTE: The control-plane ACLs support only the eq operator.
Default Not configured
Command Mode IPV4ACL
Usage
Information
OS10 cannot count both packets and bytes; when you enter the count byte options, only bytes
increment. The no version of this command removes the filter.
Example
OS10(conf-ipv4-acl)# permit tcp any any capture session 1
Supported
Releases
10.2.0E or later
permit tcp (IPv6)
Configures a filter to permit TCP packets meeting the filter criteria.
Syntax
permit tcp [A::B | A::B/x | any | host ipv6-address [eq | lt | gt | neq
| range]] [A::B | A:B/x | any | host ipv6-address [eq | lt | gt | neq |
range]] [ack | fin | psh | rst | syn | urg] [capture | count | dscp value |
fragment | log]
Parameters
A::B Enter the IPv6 address in hexadecimal format separated by colons.
A::B/x Enter the number of bits that must match the IPv6 address.
any (Optional) Enter the keyword any to specify any source or destination IP address.
NOTE: The control-plane ACLs do not support the any parameter.
host ipv6-address (Optional) Enter the IPv6 address to use a host address only.
capture (Optional) Capture packets the filter processes.
count (Optional) Count packets the filter processes.
byte (Optional) Count bytes the filter processes.
dscp value (Optional) Permit a packet based on the DSCP values, from 0 to 63.
fragment (Optional) Use ACLs to control packet fragments.
log (Optional) Enables ACL logging. Information about packets that match an ACL rule are logged.
Default Not configured
Command Mode IPV6-ACL
Usage
Information
OS10 cannot count both packets and bytes; when you enter the count byte options, only bytes
increment. The no version of this command removes the filter.
Example
OS10(config)# ipv6 access-list ipv6test
OS10(conf-ipv6-acl)# permit tcp any any capture session 1
Access Control Lists 1271